Everyone tests the email field for formatting. Almost no one tests it for XSS. That blind spot let Synack Red Team researcher Salman Khan turn a routine account settings field into a full attack chain. The email spec allows a "+" for subaddress tagging, and Salman used that trick to slip an XSS payload past validation and store it, unencoded, in his own profile. Then he sent a clean, normal looking invitation to a test account, no payload in the email itself, no login required to open it. The page rendered his poisoned profile the moment it loaded, and the exploit fired on mouseover. Three separate layers of validation missed it. Read how: hubs.ly/Q04vywJb0 #ExploitsExplained #PenTesting #XSS #SynackRedTeam

Aug 27, 2026 · 4:03 PM UTC

3
8
76
4,923
Sort replies: Relevant Recent Liked
Replying to @SynackRedTeam
Wow, amazing method! 🔥 The creativity behind this XSS attack chain is impressive. The write-up uses Chrome 125 has anyone tested whether this method still works on Chrome 150? 👀
1
52
Replying to @SynackRedTeam
I never understood why no one else does this
1
29
Replying to @SynackRedTeam
facebook.com/share/1HMsbsuw4… @facebook a group of kerala conversion network & south indian scammer blackmailing & blackmagic hoax on shaadi.com profiles. All from this college network...Naveen collection & IBM things. Friend request r sent from KV networks.
3